blob: 6d84c531fddc605a9d791a92c38fb7e14d2004f8 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
|
#!/bin/bash
#
# Compile configuration.
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU Affero General Public License as
# published by the Free Software Foundation, either version 3 of the
# License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU Affero General Public License for more details.
#
# You should have received a copy of the GNU Affero General Public
# License along with this program. If not, see
# <http://www.gnu.org/licenses/>.
# Load
source $APP_BASE/lib/hydra/functions || exit 1
hydra_config_load
# Config
CONFIG="$HYDRA_FOLDER/puppet/config/compiled.yaml"
NODES="`hydra $HYDRA nodes`"
FACTS="$HYDRA_FOLDER/puppet/config/facts"
KEYS="$HYDRA_FOLDER/keyring/keys/nodes"
echo "Starting a fresh compiled config..."
mkdir -p "`dirname $CONFIG`"
echo "---" > $CONFIG
echo "#" >> $CONFIG
echo "# Compiled configuration." >> $CONFIG
echo "# Do not edit this file. Use 'hydra $HYDRA compile' instead." >> $CONFIG
echo "#" >> $CONFIG
# Per-node configuration
for node in $NODES; do
# SSH public keys
if [ -e "$KEYS/$node/ssh/id_rsa.pub.asc" ]; then
echo "Adding SSH public key for $node..."
key="ssh_authorized_key::$node"
value="$(keyringer $HYDRA decrypt nodes/$node/ssh/id_rsa.pub 2> /dev/null | cut -d ' ' -f 2)"
echo "$key: '$value'" >> $CONFIG
fi
done
echo "Compiling data from collected facts..."
# SSH known_hosts
echo "sshkeys:" >> $CONFIG
for node in $NODES; do
if [ -e "$FACTS/${node}.yaml" ]; then
rsakey="$(grep sshrsakey: $FACTS/${node}.yaml | cut -d ':' -f 2 | sed -e 's/ //g' -e 's/"//g')"
sshed25519key="$(grep sshed25519key: $FACTS/${node}.yaml | cut -d ':' -f 2 | sed -e 's/ //g' -e 's/"//g')"
sshecdsakey="$(grep sshecdsakey: $FACTS/${node}.yaml | cut -d ':' -f 2 | sed -e 's/ //g' -e 's/"//g')"
host_aliases=""
ssh_ports="`hydra_hiera_query $node sshd::ports`"
if [ "$ssh_ports" != "nil" ] && [ ! -z "$ssh_ports" ]; then
ssh_ports="`echo $ssh_ports | sed -e 's/\[//g' -e 's/\]//g' -e 's/,//g'`"
for port in $ssh_ports; do
if [ -z "$host_aliases" ]; then
host_aliases="'[${node}]:$port'"
else
host_aliases="$host_aliases, '[${node}]:$port'"
fi
done
fi
if [ ! -z "$rsakey" ]; then
#echo " $node-rsa:" >> $CONFIG
echo " $node:" >> $CONFIG
#echo " name : '$node'" >> $CONFIG
echo " ensure : 'present'" >> $CONFIG
echo " type : 'ssh-rsa'" >> $CONFIG
echo " key : '$rsakey'" >> $CONFIG
if [ ! -z "$host_aliases" ]; then
echo " host_aliases : [ $host_aliases ]" >> $CONFIG
fi
fi
# See [PUP-6589] Resource Type sshkey doesn't allow the declaration of multiple SSH host keys for one host
# https://tickets.puppetlabs.com/browse/PUP-6589
#if [ ! -z "$sshed25519key" ]; then
# echo " $node-sshed25519key:" >> $CONFIG
# echo " name : '$node'" >> $CONFIG
# echo " ensure: 'present'" >> $CONFIG
# echo " type : 'ssh-ed25519'" >> $CONFIG
# echo " key : '$sshed25519key'" >> $CONFIG
#fi
#if [ ! -z "$sshecdsakey" ]; then
# echo " $node-sshecdsakey:" >> $CONFIG
# echo " name : '$node'" >> $CONFIG
# echo " ensure: 'present'" >> $CONFIG
# echo " type : 'ecdsa-sha2-nistp256'" >> $CONFIG
# echo " key : '$sshecdsakey'" >> $CONFIG
#fi
fi
done
|